IceFire — Ransomware Profile
IceFire is a double-extortion ransomware family that MalwareHunterTeam first flagged in March 2022, at that point a Windows-focused encryptor. It surfaced publicly in August 2022, when NCC Group counted ten victims in its first month of activity, with technology firms accounting for roughly 90% of the targets and most victims offering web-hosting services. In March 2023 SentinelLabs documented a new Linux ELF build of the ransomware deployed inside enterprise network intrusions, with initial access gained by exploiting CVE-2022-47986, a deserialization vulnerability in IBM Aspera Faspex file-sharing software; that wave struck media and entertainment sector organisations worldwide. SentinelLabs also records IceFire victims in Turkey, Iran, Pakistan and the United Arab Emirates. Encrypted files are renamed with a .ifire extension. Leak-site trackers record no victim postings after 20 August 2022, both known onion addresses are now unreachable, and no campaign has been publicly documented since the March 2023 Linux wave, so the operation is carried here as inactive.
Vendor research
Read the full analysis on IntelFusions